MAL-2025-5829
Dashboard / Malicious Package / MAL-2025-5829
MAL-2025-5829
Summary: Malicious code in node-mongoose-orm (npm)
Details: The package employs typosquatting to impersonate a legitimate author and package, and it contains obfuscated code that exfiltrates sensitive user data and creates a backdoor for remote code execution, The core of the malicious activity is found in the `package/lib/writer.js` file. The lib/writer.js file contains obfuscated code that collects and exfiltrates data. It collects sensitive information: environment variables, OS platform, hostname, username, and MAC addresses. Sends this information via a POST request to `https://log-server-lovat.vercel.app/api/ipcheck/703`. The most dangerous part is `eval(r.data)`. This is a remote code execution (RCE) vulnerability. The server can send back any JavaScript code, and it will be executed on the user's machine
References:
Affected packages
Package
Name: node-mongoose-orm
Purl: pkg:npm/node-mongoose-orm
Affected ranges
Type: SEMVER
Events:
